CVE-2026-20182
CVE-2026-20182 is a critical authentication bypass affecting the DTLS-based control-connection handshake in Cisco Catalyst SD-WAN Controller and SD-WAN Manager. The flaw exists because, when a connecting peer declares itself to be a vHub device, the system omits device-type-specific certificate verification yet still marks the peer as authenticated. An unauthenticated remote attacker can exploit this by sending a crafted DTLS handshake sequence that bypasses authentication checks and establishes a trusted control-plane peer relationship. Once authenticated, the attacker can issue arbitrary configuration commands across the SD-WAN fabric or establish persistent administrative access. CVE-2026-20224 is an XML External Entity (XXE) injection vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. The vulnerability is caused by improper handling of XML External Entity entries during XML parsing. An unauthenticated remote attacker can send a crafted HTTP request to exploit this flaw and read arbitrary files stored on the underlying system, without requiring valid credentials. CVE-2026-20209 is a privilege escalation vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. The vulnerability exists because sensitive session information is recorded in audit logs. An authenticated remote attacker with read-only permissions can retrieve privileged session tokens from those logs and use them to perform actions as a high-privileged user. CVE-2026-20210 is a privilege escalation vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. The vulnerability is caused by a failure to redact sensitive information within device configurations and templates. An authenticated remote attacker with read-only permissions can access this exposed sensitive information and use it to elevate their privileges to those of a high-privileged user.
EPSS 83.13% · 99.3th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Catalyst SD-WAN Manager (formerly vManage); all deployment types; releases prior to 20.9.9.1, 20.12.5.4 / 20.12.6.2 / 20.12.7.1, 20.15.4.4 / 20.15.5.2, 20.18.2.2, 26.1.1.1 | |
| Cisco | Cisco Catalyst SD-WAN Controller (formerly vSmart); all deployment types (On-Prem, Cloud-Pro, Cisco Managed Cloud, FedRAMP); releases prior to 20.9.9.1, 20.12.5.4 / 20.12.6.2 / 20.12.7.1, 20.15.4.4 / 20.15.5.2, 20.18.2.2, 26.1.1.1 |
Exploit Intelligence
- Cisco Catalyst SD-WAN Peering Authentication Bypass (github-poc-repo)
- Cisco Catalyst SD-WAN Peering Authentication Bypass (github-poc-repo)
- Cisco Catalyst SD-WAN Peering Authentication Bypass (github-poc-repo)
- Cisco Catalyst SD-WAN Peering Authentication Bypass (github-poc-repo)
- Cisco Catalyst SD-WAN Peering Authentication Bypass (github-poc-repo)
- Cisco Catalyst SD-WAN Peering Authentication Bypass (github-poc-repo)
- Cisco Catalyst SD-WAN Peering Authentication Bypass (github-poc-repo)
- Cisco Catalyst SD-WAN Peering Authentication Bypass (github-poc-repo)
- Cisco Catalyst SD-WAN Peering Authentication Bypass (github-poc-repo)
- Cisco Catalyst SD-WAN Peering Authentication Bypass (github-poc-repo)
…and 110 more exploits
Timeline
- May 14, 2026 CISA KEV Added
- May 14, 2026 PoC Published
- May 14, 2026 CVE Published
- May 14, 2026 PoC Published
- May 14, 2026 PoC Published
- May 14, 2026 PoC Published
- May 14, 2026 PoC Published
- May 14, 2026 PoC Published
- May 14, 2026 PoC Published
- May 14, 2026 PoC Published
- May 14, 2026 PoC Published
- May 14, 2026 PoC Published
References
- https://ccb.belgium.be/advisories/warning-authentication-bypass-cisco-catalyst-sd-wan-can-be-exploited-gain-administrative advisory
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW#fs vendor
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R vendor
- https://nvd.nist.gov/vuln/detail/CVE-2026-20182 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-20209 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-20210 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-20224 technical